ITPEC IP April 2023 Question 41

Source exam: ITPEC IP April 2023Topic: Security

ITPEC IP April 2023 — Question 41 of 100

A vulnerability in an information asset can be exploited by a threat, and the resulting potential for damage is risk. A vulnerability is a weakness such as faulty configuration or unpatched software. A threat is a possible cause of harm, such as an attacker or disaster. Risk reflects the likelihood and impact of that threat exploiting the weakness.

Answer (b)

Why not others:
- (a) reverses threat and vulnerability and calls the damage potential a vulnerability

- (c) incorrectly treats risk as the weakness itself

- (d) incorrectly says a vulnerability exploits risk and calls the damage potential a threat

Key rule: Threat exploits vulnerability and creates risk to an asset; controls reduce likelihood, impact, or exposure.

AI-generated — may contain errors

The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.

This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official IP past-paper collection or Report an issue.